Risk level: medium. Can you change it: yes. Found in 1 breaches in this directory.
A score or label, such as weak, fair or strong, that a website calculated when you set your password and then stored alongside your account.
The score is not the password and cannot be used to log in. What it does is sort victims: a weak rating tells an attacker that a short list of common passwords will probably work. It also reveals roughly how long or complex the password is, which narrows guessing.
With your email address it becomes a targeting list for password spraying, where attackers try common passwords against the accounts most likely to fall. If the same weak password is reused elsewhere, every other account with that email address is exposed too. A strong rating offers less protection than it seems if the password was reused.
No. The score only describes how strong the password looked. It helps attackers choose targets but does not reveal the password.
Change it if you used it anywhere else. Strength does not help when the same password leaks from a second site.
Usually for analytics or to nag users with weak passwords. It should not have been stored beside account details.
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.